8 ms·
As these hacks are becoming more common place, I'd love to hear fellow HN reader's take on their password strategy/management. Many thanks in advance!
by wsr 10y ago
As these hacks are becoming more common place, I'd love to hear fellow HN reader's take on their password strategy/management. Many thanks in advance!
- K0nserv 10y agoI use the excellent 1Password, syncing over WiFi with my phone as the source of truth for my vault. 2FA enabled for everything that supports it and backup codes stored physically. Works great and password managers are one of the few times when something is both more convenient and more secure.
- chmars 10y agoIsn't it risky to have your password and your 2FA tokens in the same app, i.e., 1Password in your case?
- eddyg 10y agoAgileBits addresses this in a blog post: https://blog.agilebits.com/2015/01/26/totp-for-1password-users/ https://blog.agilebits.com/2015/01/26/totp-for-1password-use...
- K0nserv 10y agoThat's my opinion and that's why I have my 2FA tokens in a different app. Still on the same device which might not be the best.
- anc84 10y agoI simply use keepassx with the database being synced between all my devices (Linux, Windows, Android) via Syncthing. I also have a scrambled printout in my bank safe (30€/year) that I update every couple of months.
- joemccall86 10y agoKeePassX and Syncthing over WiFi. No browser add-ons. I decided to give it a try after the LastPass acquisition to see how feasible it was, and haven't looked back really. It helps that I'm mostly on Android mobile devices. KeePass2Android is what I use on the phone.
- jagermo 10y agoI'm using LastPass with a 2FA Yubikey token. In addition, I try use different E-Mail adresses whenever I sign up, a catchall makes sure they end up in the same inbox. This might not stop a sophisticated targeted attack, but it should throw off a lot of automated runs since the email they got is seemingly not used at another service. A litte obscurity to strengthen the rest of my security ;)
- jonlucc 10y agoHow does the Yubikey work? Do you have to plug it in every time you want to sign into a site?
- jagermo 10y agoNo, only once to decrypt the lastpass database. You can even set to only ask every 30 days, however I feel that this defeats the security features a little
- lukasm 10y agoDo I need premium account to use Yubikey? What happens if you lost the Yubikey?
- raesene9 10y agoI use a password safe file (https://pwsafe.org/ https://pwsafe.org/) which I then store randomly generated passwords per site and have a strong password on the safe itself. I like this as a solution as it's not dependent on any third parties like cloud services, its pretty portable and I have a unique password per site, so I'm not really that bothered when the inevitable breaches happen. Downside to this approach is that I have to have a device which has the password safe to hand to use it (there are clients for Windows/Linux/Mac/iOS/Android), I'm responsible for managing the file and if I lose the file + passphrase I'm stuffed :)
- peteretep 10y agoRandom password, FastMail email alias, fake but plausible name and date or birth, all dumped in to 1Password. Would love to find a credit card which allowed me to offer up fake billing details - obviously the CC provider would need to know who I was, but there's no reason who I'm paying needs to.
- scrollaway 10y agoUse a password manager. One strong password per site. https://www.keepassx.org/ https://www.keepassx.org/ Also, use 2FA wherever available. Google Authenticator is good enough. Store your backup codes somewhere safe (your keepass db, for example. Although that goes a bit counter to the point of 2FA, if someone cracks your keepass db, you're pretty screwed regardless).
- chmars 10y agoThere is still a major annoyance with Google Authenticator etc.: When you switch your device, you have to set up your 2FA credentials again …
- jjnoakes 10y agoI store the original 2fa seed somewhere offline and safe (wallet, safe, etc) so that I can bootstrap a new auth device at will.
- Yhippa 10y agoThis is why I now use SMS authentication.
- chmars 10y agoI do sometimes too … although it is less secure … and if you are abroad, it can be expensive due to roaming charges … or you are not online at all …
- scrollaway 10y agoNot only do you get the same issue with SMS authentication (have to set it up again when you get a new number), but on top of it SMS auth is not as readily available and has proprietary requirements (namely, you have to have a mobile number with text support, it has to be available at your current location, it may cost money, the auth service has to support whichever country code you're under, ...). Also, as other people mentioned, it's technically possible to back up your initial seed. SMS auth is a disgrace, when we have 2fa standards.
- edent 10y agoA unique password, 2FA, AND a unique email address. I use https://lastpass.com/ https://lastpass.com/ for generating passwords. $12/year and works on Linux & Android. Would prefer open source, but nothing else comes close. I tend to generate 32 char passwords with a mix of upper, lower, number, and special. Only a few websites insist on shorter passwords - or have character restrictions. For 2FA I use either SMS or Authy https://www.authy.com/ https://www.authy.com/ Take a look at https://www.turnon2fa.com/ https://www.turnon2fa.com/ to see which sites support 2FA. It does make logging in to some frequently used sites a bit of a pain (looking at you PayPal!) but I think it is worth it. On to unique email addresses. I do this for two reasons. 1. Allows me to easily see where an email has come from & filter if necessary. I can tell if your company has leaked / lost / sold my address. 2. If I have reused a password, a database leak doesn't compromise other sites. An attacker doesn't know the login details for LinkedIn based on my GoToMyPC email. I tend to use something like lnkdn@ mydomain / gtmypc@ ... / twttr@ ... - but if your mail provider lets you use a catch-all, it can be anything you like. One word of warning - it really confuses people when you give the email over the phone! I usually say "I'm creating a unique email address for you so that the message doesn't go into spam. Ok? sound of me hitting random keys It's yourcompany@ ...."
- jagermo 10y agoHa, just like my setup. And yes, it does confuse people, to a lot of them it seems like magic.
- acmecorps 10y agoGood idea on (2). I have a gmail account, so I just use myaccount+whatever_service@gmail.com. Pretty handy.
- tonmoy 10y agoIf a lot of people start doing this thing, then it will be trivial for an attacker to figure out name+service1@domain can be changed to name+service2@domain
- 10y ago
- altitudinous 10y agoI only use Apple on a daily basis, so I use the inbuilt iCloud Keychain which syncs my passwords across Apple devices. I use the built in password generator to generate secure passwords that are unique for each website. For the times I do log in to a PC, I can call up my passwords on my iPhone to type them in manually.
- amelius 10y agoI'm hashing my passwords. For example, when logging into any google service, I use: echo "secret123|google" | sha1sum where "secret123" is my master password (I use a much longer one actually to be safe). Similarly, on facebook, I woudl use: echo "secret123|facebook" | sha1sum To both passwords, I add "Aa1!" to make it pass the capital/lowercase etc. tests. EDIT: it is best to write a script for this
- brillenfux 10y agoSomebody has told me, that this would be bad because "something" (I think entropy?). I didn't understand that. Can somebody with sense please explain if this is a good or bad idea?
- jhasse 10y agoIt's a good idea if you're using a secure secret or if an attacker doesn't know your exact method.
- tacostakohashi 10y agoIt's not a terrible idea, but it does fall apart if you need to change one of the passwords (say, because you were using this strategy for a number of services including gotomypc). Now you need to have multiple master passwords, or you need to increment the service name (gotomypc2?), and then you're remembering the increment as well as the service and master password. It's a cute trick, but I don't think it really scales well for the number of accounts we tend to have these days, and the frequency with which passwords must be changed due to hacks, password aging policies, validation ("must have 1 punctuation character"), etc. As for entropy, it's limited by the master password, and whatever obscurity the hashing and service name provide. If you have a short master password, you're not getting the as much uniqueness as you might think by looking at the length of the hash output.
- Glyptodon 10y agoI do something similar but I'm not happy about it at all. But I'm also afraid of password managers themselves becoming compromised.
- jhasse 10y agoI'm using this password calculator: https://extensions.gnome.org/extension/825/password-calculator/ https://extensions.gnome.org/extension/825/password-calculat... It's basically a SHA1 of an alias and a secret (similar to amelius' approach https://news.ycombinator.com/item?id=11932624 https://news.ycombinator.com/item?id=11932624). I've also started recoding the extension for Windows and other DEs: https://github.com/jhasse/pwcalculator https://github.com/jhasse/pwcalculator
- Xunxi 10y agoI use the free version of Maskme or Blur from Abine https://www.abine.com/index.html https://www.abine.com/index.html
- xrisk 10y agoI use https://www.passwordstore.org/ https://www.passwordstore.org/ to generate passwords which are then encrypted using my GPG keys. My passwords directory is a git repo which I sync to GitHub. Since I don't possess a Yubikey or similar, I've stored a copy of my secret key in Protonmail.
- lukasm 10y agoWhat is your threat model? If this is the just the described hacking I propose -> https://www.troyhunt.com/going-dark-online-privacy-and-anonymity-for-normal-people/ https://www.troyhunt.com/going-dark-online-privacy-and-anony... https://vox.space/blog/89/being-privacy-aware-in-2016 https://vox.space/blog/89/being-privacy-aware-in-2016 Get anonymous identity and VPN. Using KeePassX/LastPass/1Password is a bit problematic. They become a single point of failure. Someone can get my master password (https://github.com/cxxr/lostpass https://github.com/cxxr/lostpass) or can pwn LastPass. To improved that my passwords becomes <last_pass_gen_pass> + <random_nonce_that_i_know_how_to_generate_in_my_head> + <helper_password> I divided accounts into tiers: Tier0: The most important account: Macbook, Gmail, Github Tier1: Still important, but not as much as Tier0: Youtube Tier2: I don't really care. Tier3: Testing accounts for local dev server: Single simple password like qwerty1234. I just need to remember 5 passwords(Gmail, Macbook, Github, LastPass, helper password). I think this strategy gives a nice balance between connivance and security.
- zeta0134 10y agoI have a "things I don't care about password" that's long, easy to type, and easy to remember. It's about 20 characters, which is sufficient for most services that don't have two-factor authentication, but annoying because some archaic systems STILL have a maximum password limit for ridiculous reasons that suggest one-way hashes are not being used. Wherever two-factor is available, it's turned on. Usually through my phone, which has its own passcode and won't display text messages on my screen. I'm curious as to how secure this really is, but I suspect this is reasonably difficult enough to hack that someone would have to be targeting me specifically to be able to reliably pull my SMS token out of the air and match it up to my login before I used it within a few seconds and invalidated it. If someone decides to target me specifically, I have bigger problems. For my email, my banking sites, and all the things that I really would rather someone else please not log into, I have a unique password. This is still long and easy to type; the only advantage of these passwords is that I am sure to not share them in any modified form anywhere else on the internet, which protects against these sorts of cross-site password theft attacks. (Even for my shared password I have a pattern that makes it uniqueish, but that pattern is simple enough that a human could probably reverse engineer it.) The only real exception to this strategy is things that can be password-less, though that carries its own weirdness. All of my remotely-accessible SSH servers use private key authentication and have passwords enabled for sudo, but don't allow SSHing in using that password. (So they are effectively single-factor for login and userland access, which can still do a lot of damage but requires a computationally difficult key, and two-factor for root access.) This carries its own issues; I have to keep my private key files somewhere, and even if I use multiple keys for each machine I log in from, all it takes is one rogue login to hose my server. I either put all my eggs into one basket by using some sort of encrypted store, or I spread out my attack surface, increasing its complexity, and decreasing the chance that I'll have successfully patched all the holes up. I also don't like that there's no way I could reasonably memorize a private key, so the option of NOT storing it kind of doesn't exist. At best I can try to protect the key in some way.
- ams6110 10y agoI use passwordstore. https://www.passwordstore.org/ https://www.passwordstore.org/ It simply manages gpg-encrypted files in a directory hierarchy. Very flexible to set up whatever organization makes sense for you. I find it suits my needs.